Skip to content
khalidsaidiPublic

About

Daily CZDS zone-file trend engine (counts + deltas + signals per TLD)

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

RootFetch

Delegation intelligence from DNS-visible evidence, not marketing claims.

RootFetch computes structural movement in the global namespace from CZDS zone snapshots. It runs locally (no raw zone publishing), produces versioned model outputs (DVI + regime classification), and publishes immutable read-only artifacts for analysis, replay, alerting, and AI agents.

Positioning

RootFetch is the verifiable structural layer, not a full threat-intelligence suite.

  • Use RootFetch for immutable run evidence, replay/compare workflows, and agent-ready deterministic outputs.
  • Use broad intel platforms for enrichment breadth and multi-signal threat context.
  • Use both together when you need narrative speed plus citation-grade structural proof.

Core Outputs

  • DVI_v1: bounded 0-100 volatility index (dispersion + concentration delta + anomaly clustering)
  • Regime_v1: state machine with thresholds + hysteresis + minimum duration + confidence score
  • Immutable artifacts: data/artifacts/runs/<run_id>/... with manifest.json (size + sha256)

Guarantees

  • Immutable run artifacts (cacheable for 1 year)
  • Atomic latest.json pointer (no mixed reads)
  • Auditable alert delivery (at-least-once + durable dedup + dead-letter)
  • Static site on GitHub Pages: no servers, no hosting bill

Operating Model

  • .github/workflows/daily.yml runs every day at 03:30 UTC on GitHub Actions (free for public repos): it fetches counts from CZDS, commits them under data/, rebuilds the site with scripts/build_site.py, and deploys it to rootfetch.com on GitHub Pages.
  • The run fails, and GitHub emails the repo owner, when the newest data is more than 3 days old.
  • Build the site locally with python scripts/build_site.py (output in _site/).
  • Two ingestion modes:
    • Day-1 baseline: ingest all approved CZDS TLDs in one resumable run.
    • Daily hybrid (after baseline completion): core set daily + deterministic rolling long tail.

Primary Metric

  • count_ns_sld: unique second-level owners with at least one NS record.

This is a delegation footprint proxy, not total registrations.

Safety

  • Never commit credentials/tokens/MFA seeds.
  • Never commit .env files.
  • Never commit raw zone files (*.gz, *.zone, *.txt.gz).
  • Commit only safe aggregates under data/ and code/docs.

Setup

python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"

Set local env vars with a local credential file (.env.czds recommended; .env remains legacy-compatible):

  • CZDS_USERNAME
  • CZDS_PASSWORD
  • optional CZDS_TOTP_SECRET

Quick start:

cp .env.example .env.czds
chmod 600 .env.czds
rootfetch auth-check

Optional local MCP endpoint override for step-9 live checks (keep this local-only, never commit):

cat > .env.mcp <<'EOF'
ROOTFETCH_MCP_URL=https://rootfetch.com/mcp
EOF
chmod 600 .env.mcp

CLI

rootfetch auth-check
rootfetch discover
rootfetch run-baseline --dry-run
rootfetch run-baseline --resume
rootfetch baseline-status
rootfetch run-hybrid
rootfetch run-hybrid --dry-run
rootfetch compute-signals --date YYYY-MM-DD
python compute_model_v1.py snapshot.json
rootfetch rag build
rootfetch rag build-static
rootfetch rag search "count_ns_sld"
rootfetch mcp serve --transport stdio
rootfetch alerts run --date YYYY-MM-DD
rootfetch alerts run --date YYYY-MM-DD --recover-corrupt-state
rootfetch publish prepare --date YYYY-MM-DD --out-dir .ai/publish/latest
rootfetch publish run --source-dir .ai/publish/latest --artifacts-root data/artifacts --model-version rootfetch_model_v1 --snapshot-ts-utc 2026-02-25T23:15:01Z

Local Automation

Primary daily entrypoint:

./scripts/local_run_hybrid.sh

Full retest entrypoint (includes MCP checks when MCP URL is configured):

./scripts/retest_new_approvals.sh

Both run scripts load local env files in this order: .env.czds -> .env -> .env.mcp.

The script auto-switches:

  1. runs rootfetch discover
  2. if baseline is incomplete, repeatedly runs rootfetch run-baseline --resume until 100% coverage
  3. once baseline is complete, runs rootfetch run-hybrid
  4. rebuilds static RAG + commits safe artifacts only

See scheduler setups in docs/local_runner.md.

Outputs

  • data/approved_tlds/latest.json
  • data/daily_counts/<YYYY-MM-DD>.csv
  • data/growth_trends.csv
  • data/signals/*
  • data/digests/*
  • data/rag/rag_chunks.json
  • data/rag/rag_meta.json
  • data/artifacts/latest.json
  • data/artifacts/replay/index.json
  • data/artifacts/runs/<run_id>/*
  • data/state/baseline_complete.json (written once baseline reaches 100%)

Docs

RootFetch is a read-only intelligence layer. If it is not in the artifacts, it did not happen.

GitHub Actions

  • .github/workflows/rootfetch_daily.yml runs scheduled ingestion and publish.
  • .github/workflows/release.yml runs CI tests/build checks.
  • .github/workflows/gcp_deploy.yml deploys web + telemetry services to GCP on safe artifact/code changes.

About

Daily CZDS zone-file trend engine (counts + deltas + signals per TLD)

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages